Senior Product Security Engineer

Posted Yesterday
Be an Early Applicant
Hiring Remotely in Nānakrāmguda, Rangareddi, Telangāna, IND
Remote
Senior level
Healthtech
The Role
Leads product cybersecurity across the medical device lifecycle, including risk assessments, threat modeling, security architecture reviews, penetration testing, vulnerability management, secure code reviews, and regulatory compliance. Collaborates with engineering, quality, regulatory, and product teams to secure connected devices, applications, embedded systems, and cloud healthcare platforms. Supports DevSecOps, coordinated vulnerability disclosure, post-market cybersecurity, security metrics, automation, and remediation verification.
Summary Generated by Built In

Careers that change lives start here. Medtronic is a global leader in healthcare technology with a Mission to alleviate pain, restore health, and extend life. Our 95,000 employees work across more than 150 countries to put patients first — developing innovative medical technologies that improve the lives of 72+ million patients each year. Your unique talents will help shape the future of healthcare while building a career grounded in purpose, growth, and impact.

A Day in the LifeThe Product Security function within Research & Development is responsible for integrating cybersecurity throughout the product lifecycle for medical devices, connected healthcare solutions, software applications, embedded products, and cloud-connected healthcare systems. The team partners closely with R&D, Systems Engineering, Quality, Regulatory, and Product teams to support secure product development, cybersecurity risk management, vulnerability management, regulatory compliance, and post-market cybersecurity activities across Class I, Class II, and Class III medical devices.
This position is based in Hyderabad, India and follows a Flex work arrangement. No travel is required.

As a Senior Product Security Engineer, you will drive product security activities across the product lifecycle, including security risk assessments, threat modeling, security architecture reviews, penetration testing, vulnerability management, and compliance with medical device cybersecurity regulations and standards. This role supports medical devices, connected care platforms, software applications, and cloud-connected healthcare systems while collaborating with cross-functional teams to integrate cybersecurity into product development processes.

Primary Responsibilities

  • Perform security risk assessments throughout the product development lifecycle.
  • Conduct threat modeling activities using methodologies such as STRIDE, Attack Trees, MITRE ATT&CK, CVSS, and similar frameworks.
  • Identify product security requirements and support implementation of appropriate security controls.
  • Review system, software, cloud, and network architectures from a security perspective.
  • Collaborate with development teams to design secure products and mitigate identified risks.
  • Plan and execute security testing activities including vulnerability assessments, penetration testing, secure code reviews, security regression testing, protocol security testing, and network security testing.
  • Analyze, prioritize, and track vulnerabilities through remediation and verification activities while supporting coordinated vulnerability disclosure and post-market cybersecurity processes.
  • Integrate cybersecurity activities into product development processes, support security design reviews, security architecture assessments, security impact assessments, security KPIs, security metrics, automation initiatives, and DevSecOps practices.

Required Qualifications

  • Bachelor's degree OR Master's degree in Computer Science, Cybersecurity, Information Technology, Software Engineering, or Electronics & Communication Engineering with 8+ years of experience in Product Security, Application Security, Cybersecurity Engineering, or Medical Device Security.
  • Experience working with connected products, embedded systems, desktop applications, cloud services, Internet of Things (IoT) platforms, or healthcare technology products.
  • Experience in security risk assessments, threat modeling, security architecture reviews, security requirements engineering, vulnerability assessments, penetration testing, secure code reviews, network security testing, and web/API security testing.
  • Experience with security tools including Burp Suite, OWASP ZAP, Nessus, Nmap, Wireshark, Metasploit, or similar application and infrastructure security tools.
  • Experience developing scripts and automation tools using Python and supporting Secure Software Development Lifecycle (SSDLC), DevSecOps, vulnerability management, and security automation activities.

Preferred Qualifications

  • Experience securing Class I, Class II, and Class III medical devices, connected healthcare solutions, Software as a Medical Device (SaMD), or cloud-connected healthcare systems.
  • Knowledge of FDA Cybersecurity Guidance, IEC 81001-5-1, AAMI TIR57, AAMI TIR97, IEC 62304, ISO 14971, and NIST 800-53.
  • Experience with Software Bill of Materials (SBOM), dependency analysis, coordinated vulnerability disclosure, and post-market cybersecurity activities.
  • Knowledge of cloud security in Microsoft Azure and Amazon Web Services (AWS) environments.
  • Knowledge of authentication and authorization technologies, cryptography fundamentals, and secure communication protocols including TLS, HTTPS, and MQTT. 

Physical Job Requirements
The above statements are intended to describe the general nature and level of work being performed by employees assigned to this position, but they are not an exhaustive list of all the required responsibilities and skills of this position. 

‌

‌



Recruitment Fraud Alert 

We are aware of phishing scams targeting job seekers. Please keep the following in mind: 


Apply only through official Medtronic channels. All legitimate Medtronic recruiting communications come from approved Medtronic platforms and official @medtronic.com email addresses. 


Medtronic will never ask for payment or sensitive personal information (such as bank account or Social Security details) during early stages of the hiring process. Any such requests are not legitimate. 


If you receive a suspicious message claiming to be from Medtronic, do not respond, click links, or open attachments. 


If you have any questions, concerns regarding the authenticity of a communication alleged to have been made by or on behalf of Medtronic, please contact us immediately at [email protected]. 

Benefits & Compensation

Medtronic offers a competitive Salary and flexible Benefits Package
A commitment to our employees lives at the core of our values. We recognize their contributions. They share in the success they help to create.  We offer a wide range of benefits, resources, and competitive compensation plans designed to support you at every career and life stage.
 



‌

This position is eligible for a short-term incentive called the Medtronic Incentive Plan (MIP).

Skills Required

  • Bachelor’s or master’s degree in Computer Science, Cybersecurity, Information Technology, Software Engineering, or Electronics and Communication Engineering
  • 8+ years of experience in Product Security, Application Security, Cybersecurity Engineering, or Medical Device Security
  • Experience with connected products, embedded systems, desktop applications, cloud services, IoT platforms, or healthcare technology products
  • Experience in security risk assessments, threat modeling, security architecture reviews, security requirements engineering, vulnerability assessments, penetration testing, secure code reviews, network security testing, and web/API security testing
  • Experience with Burp Suite, OWASP ZAP, Nessus, Nmap, Wireshark, Metasploit, or similar security tools
  • Experience developing scripts and automation tools using Python
  • Experience supporting SSDLC, DevSecOps, vulnerability management, and security automation activities
  • Experience securing Class I, Class II, and Class III medical devices, connected healthcare solutions, SaMD, or cloud-connected healthcare systems
  • Knowledge of FDA Cybersecurity Guidance, IEC 81001-5-1, AAMI TIR57, AAMI TIR97, IEC 62304, ISO 14971, and NIST 800-53
  • Experience with SBOM, dependency analysis, coordinated vulnerability disclosure, and post-market cybersecurity activities
  • Knowledge of cloud security in Microsoft Azure and AWS environments
  • Knowledge of authentication and authorization technologies, cryptography fundamentals, TLS, HTTPS, and MQTT

Medtronic Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Medtronic and has not been reviewed or approved by Medtronic.

  • Healthcare Strength — Health coverage is considered comprehensive, with high-quality medical, dental, and vision options through major providers and added mental-health resources. These programs are frequently highlighted as a core strength of the package.
  • Parental & Family Support — Parental and family benefits stand out, including up to 24 weeks paid leave for U.S. birthing parents, 12 weeks for other parents, and a global Family Care Leave at 100% pay. Family-building support (fertility, adoption/surrogacy reimbursements) and backup care further reinforce this strength.
  • Retirement Support — A 401(k) with company match is described as competitive and reliable for long-term savings. Additional financial programs, such as tuition assistance and charitable-gift matching, complement retirement planning.

Medtronic Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Dublin
80,303 Employees
Year Founded: 1949

What We Do

Medtronic is a global healthcare solutions company operating in approximately 160 countries. We are committed to improving lives through our medical technologies, services, and solutions. Since our beginning, 60 years ago, our Mission has remained the same: to alleviate pain, restore health, and extend life for people around the world. The Mission is our ethical framework and inspirational goal guiding our day-to-day work. It reminds us that our efforts are transforming millions of lives each year. To meet the needs of patients and healthcare professionals around the globe, we operate from more than 370 locations in approximately 160 countries.

Similar Jobs

Atlassian Logo Atlassian

Security Engineer

Cloud • Information Technology • Productivity • Security • Software • App development • Automation
Remote
India
11000 Employees
In-Office or Remote
2 Locations
175633 Employees

Motive Logo Motive

Operations Manager

Artificial Intelligence • Fintech • Hardware • Information Technology • Sales • Software • Transportation
Easy Apply
Remote
India
4000 Employees
Remote or Hybrid
2 Locations
175633 Employees

Similar Companies Hiring

Granted Thumbnail
Artificial Intelligence • Healthtech • Insurance • Mobile • Financial Services
New York, New York
23 Employees
OneImaging Thumbnail
Healthtech
Miami, FL
62 Employees
Vitalize Thumbnail
Artificial Intelligence • Healthtech • Software
US
50 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account